“Identity Standards Updates - Bringing Government and ... · “Identity Standards Updates –...

53
“Identity Standards Updates – FIDO” Brett McDowell, Executive Director, FIDO Alliance [email protected] 1

Transcript of “Identity Standards Updates - Bringing Government and ... · “Identity Standards Updates –...

Page 1: “Identity Standards Updates - Bringing Government and ... · “Identity Standards Updates – FIDO” Brett McDowell, Executive Director, FIDO Alliance brett@fidoalliance.org 1

“Identity Standards Updates – FIDO”

Brett McDowell, Executive Director, FIDO Alliance [email protected]

1

Page 2: “Identity Standards Updates - Bringing Government and ... · “Identity Standards Updates – FIDO” Brett McDowell, Executive Director, FIDO Alliance brett@fidoalliance.org 1

AGENDA

2

The Problem

The Solution

The Alliance

Updates

Page 3: “Identity Standards Updates - Bringing Government and ... · “Identity Standards Updates – FIDO” Brett McDowell, Executive Director, FIDO Alliance brett@fidoalliance.org 1

783 data breaches in 2014

Data Breaches…

>1 billion records since 2012

3

$3.5 million cost/breach

Page 4: “Identity Standards Updates - Bringing Government and ... · “Identity Standards Updates – FIDO” Brett McDowell, Executive Director, FIDO Alliance brett@fidoalliance.org 1

“76% of 2012 network

intrusions exploited weak

or stolen credentials” 2013 Data Breach Investigations Report 4

Page 5: “Identity Standards Updates - Bringing Government and ... · “Identity Standards Updates – FIDO” Brett McDowell, Executive Director, FIDO Alliance brett@fidoalliance.org 1

The world has a PASSWORD PROBLEM

5

Page 6: “Identity Standards Updates - Bringing Government and ... · “Identity Standards Updates – FIDO” Brett McDowell, Executive Director, FIDO Alliance brett@fidoalliance.org 1

ONE-TIME PASSCODES Improve security but aren’t easy enough to use

Still Phishable

User Confusion

Token Necklace

SMS Reliability

6

Page 7: “Identity Standards Updates - Bringing Government and ... · “Identity Standards Updates – FIDO” Brett McDowell, Executive Director, FIDO Alliance brett@fidoalliance.org 1

WE NEED A NEW MODEL

7

Page 8: “Identity Standards Updates - Bringing Government and ... · “Identity Standards Updates – FIDO” Brett McDowell, Executive Director, FIDO Alliance brett@fidoalliance.org 1

WE CALL OUR NEW MODEL

Fast IDentity Online online authentication using

public key cryptography

8

Page 9: “Identity Standards Updates - Bringing Government and ... · “Identity Standards Updates – FIDO” Brett McDowell, Executive Director, FIDO Alliance brett@fidoalliance.org 1

9

AGENDA

The Problem

The Solution

The Alliance

Updates

Page 10: “Identity Standards Updates - Bringing Government and ... · “Identity Standards Updates – FIDO” Brett McDowell, Executive Director, FIDO Alliance brett@fidoalliance.org 1

THE OLD PARADIGM

10

USABILITY SECURITY

Page 11: “Identity Standards Updates - Bringing Government and ... · “Identity Standards Updates – FIDO” Brett McDowell, Executive Director, FIDO Alliance brett@fidoalliance.org 1

THE FIDO PARADIGM

11

Poor Easy

We

ak

Str

on

g

USABILITY

SEC

UR

ITY

Page 12: “Identity Standards Updates - Bringing Government and ... · “Identity Standards Updates – FIDO” Brett McDowell, Executive Director, FIDO Alliance brett@fidoalliance.org 1

12

HOW OLD AUTHN WORKS

ONLINE

The user authenticates themselves online by presenting

a human-readable secret

Page 13: “Identity Standards Updates - Bringing Government and ... · “Identity Standards Updates – FIDO” Brett McDowell, Executive Director, FIDO Alliance brett@fidoalliance.org 1

13

HOW FIDO AUTHN WORKS

AUTHENTICATOR

LOCAL ONLINE

The user authenticates “locally” to their device

by various means

The device authenticates the user online using

public key cryptography

Page 14: “Identity Standards Updates - Bringing Government and ... · “Identity Standards Updates – FIDO” Brett McDowell, Executive Director, FIDO Alliance brett@fidoalliance.org 1

online authentication using public key cryptography

14

Page 15: “Identity Standards Updates - Bringing Government and ... · “Identity Standards Updates – FIDO” Brett McDowell, Executive Director, FIDO Alliance brett@fidoalliance.org 1

Passwordless Experience (UAF Standards)

Second Factor Experience (U2F Standards)

15 *There are other types of authenticators

Second Factor Challenge

1

Authenticated Online

3

Insert Dongle* / Press Button

2

Biometric Verification*

2

Authentication Challenge

1

?

Authenticated Online

3

Page 16: “Identity Standards Updates - Bringing Government and ... · “Identity Standards Updates – FIDO” Brett McDowell, Executive Director, FIDO Alliance brett@fidoalliance.org 1

FIDO Registration

16

Invitation Sent New Keys Created

Pubic Key Registered With Online Server

User is in a Session Or

New Account Flow

1 2 3

4

Registration Complete

User Approval

Page 17: “Identity Standards Updates - Bringing Government and ... · “Identity Standards Updates – FIDO” Brett McDowell, Executive Director, FIDO Alliance brett@fidoalliance.org 1

17

Login Complete

FIDO Authentication

FIDO Challenge Key Selected & Signs

Signed Response verified using Public Key Cryptography

User needs to login or authorize a transaction

1 2 3

4

User Approval

Page 18: “Identity Standards Updates - Bringing Government and ... · “Identity Standards Updates – FIDO” Brett McDowell, Executive Director, FIDO Alliance brett@fidoalliance.org 1

18

FIDO UAF UNIVERSAL AUTHENTICATION FRAMEWORK

AUTHENTICATOR

Same User as enrolled before?

Same Authenticator as registered before?

Page 19: “Identity Standards Updates - Bringing Government and ... · “Identity Standards Updates – FIDO” Brett McDowell, Executive Director, FIDO Alliance brett@fidoalliance.org 1

19

THE BUILDING BLOCKS FIDO USER DEVICE RELYING PARTY

WEB SERVER

FIDO SERVER

TLS Server Key

BROWSER/APP

FIDO AUTHENTICATOR

FIDO CLIENT

ASM

Authentication Private Keys

Attestation Private Keys

Cryptographic Authentication

Public Keys DB

FIDO

Authenticator Metadata

& Attestation Trust Store

UPDATE

Page 20: “Identity Standards Updates - Bringing Government and ... · “Identity Standards Updates – FIDO” Brett McDowell, Executive Director, FIDO Alliance brett@fidoalliance.org 1

20

FIDO Server FIDO Authenticator

Metadata

Signed

Attestation

Object

Verify Trust Anchor

(Available from

Metadata Service or

Other Source)

Understand Authenticator Characteristic

(Using Info From Metadata or Other Source)

ATTESTATION & METADATA

Page 21: “Identity Standards Updates - Bringing Government and ... · “Identity Standards Updates – FIDO” Brett McDowell, Executive Director, FIDO Alliance brett@fidoalliance.org 1

21

UAF AUTHENTICATION

DEMO EXAMPLE

STEP 1

Page 22: “Identity Standards Updates - Bringing Government and ... · “Identity Standards Updates – FIDO” Brett McDowell, Executive Director, FIDO Alliance brett@fidoalliance.org 1

22

UAF AUTHENTICATION

DEMO EXAMPLE

STEP 2

Page 23: “Identity Standards Updates - Bringing Government and ... · “Identity Standards Updates – FIDO” Brett McDowell, Executive Director, FIDO Alliance brett@fidoalliance.org 1

23

UAF AUTHENTICATION

DEMO EXAMPLE

STEP 3

Page 24: “Identity Standards Updates - Bringing Government and ... · “Identity Standards Updates – FIDO” Brett McDowell, Executive Director, FIDO Alliance brett@fidoalliance.org 1

24

UAF AUTHENTICATION

DEMO EXAMPLE

STEP 4

Page 25: “Identity Standards Updates - Bringing Government and ... · “Identity Standards Updates – FIDO” Brett McDowell, Executive Director, FIDO Alliance brett@fidoalliance.org 1

25

FIDO U2F UNIVERSAL 2ND FACTOR

AUTHENTICATOR

USER VERIFICATION FIDO AUTHENTICATION

Same authenticator as registered

before?

Is a user present?

Same user as enrolled

before?

Page 26: “Identity Standards Updates - Bringing Government and ... · “Identity Standards Updates – FIDO” Brett McDowell, Executive Director, FIDO Alliance brett@fidoalliance.org 1

26

Step 1 U2F AUTHENTICATION DEMO EXAMPLE

Page 27: “Identity Standards Updates - Bringing Government and ... · “Identity Standards Updates – FIDO” Brett McDowell, Executive Director, FIDO Alliance brett@fidoalliance.org 1

27

Step 2 U2F AUTHENTICATION DEMO EXAMPLE

Page 28: “Identity Standards Updates - Bringing Government and ... · “Identity Standards Updates – FIDO” Brett McDowell, Executive Director, FIDO Alliance brett@fidoalliance.org 1

28

Step 3 U2F AUTHENTICATION DEMO EXAMPLE

Page 29: “Identity Standards Updates - Bringing Government and ... · “Identity Standards Updates – FIDO” Brett McDowell, Executive Director, FIDO Alliance brett@fidoalliance.org 1

29

Step 4 U2F AUTHENTICATION DEMO EXAMPLE

+Bob

Page 30: “Identity Standards Updates - Bringing Government and ... · “Identity Standards Updates – FIDO” Brett McDowell, Executive Director, FIDO Alliance brett@fidoalliance.org 1

USABILITY, SECURITY and

PRIVACY 30

Page 31: “Identity Standards Updates - Bringing Government and ... · “Identity Standards Updates – FIDO” Brett McDowell, Executive Director, FIDO Alliance brett@fidoalliance.org 1

31

No 3rd Party in the Protocol

No Secrets on the Server side

Biometric Data (if used) Never Leaves Device

No Link-ability Between Services

No Link-ability Between Accounts

Page 32: “Identity Standards Updates - Bringing Government and ... · “Identity Standards Updates – FIDO” Brett McDowell, Executive Director, FIDO Alliance brett@fidoalliance.org 1

Better Security for online services

Reduced cost for the enterprise

Simpler and Safer for consumers 32

Page 33: “Identity Standards Updates - Bringing Government and ... · “Identity Standards Updates – FIDO” Brett McDowell, Executive Director, FIDO Alliance brett@fidoalliance.org 1

33

AGENDA

The Problem

The Solution

The Alliance

Updates

Page 34: “Identity Standards Updates - Bringing Government and ... · “Identity Standards Updates – FIDO” Brett McDowell, Executive Director, FIDO Alliance brett@fidoalliance.org 1

The Fast IDentity Online (FIDO)

Alliance is an open industry

association of over 220 global

member organizations

34

Page 35: “Identity Standards Updates - Bringing Government and ... · “Identity Standards Updates – FIDO” Brett McDowell, Executive Director, FIDO Alliance brett@fidoalliance.org 1

Board Members

35

Services/Networks

Devices/Platforms Vendors/Enablers

35 35 35

Page 36: “Identity Standards Updates - Bringing Government and ... · “Identity Standards Updates – FIDO” Brett McDowell, Executive Director, FIDO Alliance brett@fidoalliance.org 1

FIDO Alliance Mission

Develop Specifications

Operate Adoption Programs

Pursue Formal Standardization

36

1 2 3

Page 37: “Identity Standards Updates - Bringing Government and ... · “Identity Standards Updates – FIDO” Brett McDowell, Executive Director, FIDO Alliance brett@fidoalliance.org 1

37

Physical-to-digital identity

User Management

Authentication

Federation

Single

Sign-On

Passwords Risk-Based Strong

MODERN

AUTHENTICATION

FIDO SCOPE

Page 38: “Identity Standards Updates - Bringing Government and ... · “Identity Standards Updates – FIDO” Brett McDowell, Executive Director, FIDO Alliance brett@fidoalliance.org 1

38

AGENDA

The Problem

The Solution

The Alliance

Updates

Page 39: “Identity Standards Updates - Bringing Government and ... · “Identity Standards Updates – FIDO” Brett McDowell, Executive Director, FIDO Alliance brett@fidoalliance.org 1

FIDO TIMELINE

39

FIDO 1.0 FINAL First

Deployments Specification Review Draft

FIDO Ready Program

Alliance Announced

FEB 2013

6 Members

DEC 2013

FEB 2014

FEB-OCT 2014

DEC 9 2014

MAY 2015

TODAY >220

Members

Broad Adoption

JUNE 2015

Certification Program

New U2F Transports

Page 40: “Identity Standards Updates - Bringing Government and ... · “Identity Standards Updates – FIDO” Brett McDowell, Executive Director, FIDO Alliance brett@fidoalliance.org 1

40

“PayPal and Samsung Enable Consumer Payments with Fingerprint Authentication on New Samsung Galaxy S5”, Feb 24, 2014

“Secure Consumer Payments Enabled for Alipay Customers with Easy-to-Use Fingerprint Sensors on Recently-Launched Samsung Galaxy S5”, September 17, 2014

“Google Launches Security Key, World’s First Deployment of Fast Identity Online Universal Second Factor (FIDO U2F) Authentication”, October 21, 2014

2014 FIDO ADOPTION

Page 41: “Identity Standards Updates - Bringing Government and ... · “Identity Standards Updates – FIDO” Brett McDowell, Executive Director, FIDO Alliance brett@fidoalliance.org 1

41

“Microsoft Announces FIDO Support Coming to Windows 10” Feb 23, 2015

“Qualcomm launches Snapdragon fingerprint scanning technology”, March 2, 2015

“Google for Work announced Enterprise admin support for FIDO® U2F “Security Key”, April 21, 2015

“Largest mobile network in Japan becomes first wireless carrier to enhance customer experience with natural, simple and strong ways to authenticate to DOCOMO’s services using FIDO standards” May 26, 2015

2015 FIDO ADOPTION “Today, we’re adding Universal 2nd Factor (U2F) security keys as an additional method for two-step verification, giving you stronger authentication protection.” August 12, 2015

“As part of the bank’s ongoing commitment to staying ahead of advancements in mobile device authentication, the technology supporting fingerprint sign-in was built according to FIDO (Fast IDentity Online) standards.” September 15, 2015

Page 42: “Identity Standards Updates - Bringing Government and ... · “Identity Standards Updates – FIDO” Brett McDowell, Executive Director, FIDO Alliance brett@fidoalliance.org 1

42

Page 43: “Identity Standards Updates - Bringing Government and ... · “Identity Standards Updates – FIDO” Brett McDowell, Executive Director, FIDO Alliance brett@fidoalliance.org 1

Deployments are enabled by

FIDO Certified™ Products available today

43

Page 44: “Identity Standards Updates - Bringing Government and ... · “Identity Standards Updates – FIDO” Brett McDowell, Executive Director, FIDO Alliance brett@fidoalliance.org 1

44

Page 45: “Identity Standards Updates - Bringing Government and ... · “Identity Standards Updates – FIDO” Brett McDowell, Executive Director, FIDO Alliance brett@fidoalliance.org 1

45

Available to anyone Ensures interoperability Promotes the FIDO ecosystem Steps to certification:

1. Conformance Self-Validation 2. Interoperability Testing 3. Certification Request 4. Trademark License (optional)

NEXT EVENT: October 5th (U2F) fidoalliance.org/certification

Page 46: “Identity Standards Updates - Bringing Government and ... · “Identity Standards Updates – FIDO” Brett McDowell, Executive Director, FIDO Alliance brett@fidoalliance.org 1

Government Members

46

Announced June 9

46 46 46

FIDO Alliance Announces Government Membership Program – US and UK Government Agencies are First to Join

Government Agencies to Participate in Development of FIDO Standards for

Universal Strong Authentication

“The fact that FIDO has now welcomed government participation is a logical and exciting step toward further advancement of the Identity Ecosystem; we look forward to continued progress.”

Page 47: “Identity Standards Updates - Bringing Government and ... · “Identity Standards Updates – FIDO” Brett McDowell, Executive Director, FIDO Alliance brett@fidoalliance.org 1

What’s Next?

47

Page 48: “Identity Standards Updates - Bringing Government and ... · “Identity Standards Updates – FIDO” Brett McDowell, Executive Director, FIDO Alliance brett@fidoalliance.org 1

FIDO Alliance Mission

Develop Specifications

FIDO 2.0 Technology Working Group The mission of the new FIDO 2.0 Specification Technology Working Group is to consider future requirements, and to ensure widespread interoperability within the authentication ecosystem among devices, clients, and servers.

48

1

Page 49: “Identity Standards Updates - Bringing Government and ... · “Identity Standards Updates – FIDO” Brett McDowell, Executive Director, FIDO Alliance brett@fidoalliance.org 1

FIDO Alliance Mission

Operate Adoption Programs

49

2

FIDO Certification™ Program Investigating the need/feasibility of adding “security” and “biometrics” testing

FIDO UAF Metadata Service Formal launch of the UAF Metadata Service following current “soft launch”

FIDO Alliance Liaison Program Launched new program with streamlined process to foster collaboration

FIDO Marketing & Education Programs More webinars, seminars, conference talks, and targeted outreach – esp. in APAC

Page 50: “Identity Standards Updates - Bringing Government and ... · “Identity Standards Updates – FIDO” Brett McDowell, Executive Director, FIDO Alliance brett@fidoalliance.org 1

FIDO Alliance Mission

Pursue Formal Standardization

50

3

Submit mature technical Specification(s) to recognized SDO’s… • We will evaluate maturity for this purpose after more deployments • We will use the Liaison Program to collaborate with SDO’s ongoing

Page 51: “Identity Standards Updates - Bringing Government and ... · “Identity Standards Updates – FIDO” Brett McDowell, Executive Director, FIDO Alliance brett@fidoalliance.org 1

JOIN THE FIDO ECOSYSTEM

51

Page 52: “Identity Standards Updates - Bringing Government and ... · “Identity Standards Updates – FIDO” Brett McDowell, Executive Director, FIDO Alliance brett@fidoalliance.org 1

JOIN THE FIDO ALLIANCE

52

Page 53: “Identity Standards Updates - Bringing Government and ... · “Identity Standards Updates – FIDO” Brett McDowell, Executive Director, FIDO Alliance brett@fidoalliance.org 1

EXPERIENCE SIMPLER, STRONGER AUTHENTICATION

53